> -----Original Message-----
> From: Fuad Efendi [mailto:[EMAIL PROTECTED]
> 
> I think this is called "cross site scripting attack" and should be
> prevented...
> "output field" is simply a read-only widget with a value, and browsers
> should not interpret any pure HTML values of such objects...

It's not the browser though. It is the server that is updating that and 
displaying what it likes. If it chooses to inject information from another site 
then it was done at the developers choice.

Gary

*****************************************************************
The information contained in this message may be confidential or 
legally privileged and is intended for the addressee only. If you 
have received this message in error or there are any problems 
please notify the originator immediately. The unauthorised use, 
disclosure, copying or alteration of this message is 
strictly forbidden.
*****************************************************************


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to